Skip to content

Client hardening: CSP, RPC trust, unlock controls and local assets (TRR-23, TRR-26, TRR-27) #312

Description

@NeaBouli

Parent audit register: #303
Related ZKP browser task: #300
Findings: TRR-23, TRR-26 and TRR-27.

Acceptance criteria

  • Add and browser-test a strict CSP compatible only with the maintained client and explicitly approved WASM/Worker requirements.
  • Document and surface the single-RPC and prove:false trust boundary without implying light-client verification.
  • Add bounded unlock throttling and review the in-memory password lifetime.
  • Keep chain-ID binding and fail-closed signing behavior intact.
  • Serve landing/client assets locally where copies exist; do not hotlink raw GitHub assets.
  • Run browser security, accessibility, low-bandwidth, build and bundle-budget gates.

Safety boundary

No new telemetry, external origin, deployment or production wallet claim.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingjavascriptPull requests that update javascript code

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions